Hacker News new | past | comments | ask | show | jobs | submit login

This is one of the most important pieces of security advice that is often overlooked: remove your phone number from EVERYTHING.

You can also enable Advanced Protection[1] for your Google account, but other repeat offenders like Github will continue to allow SMS fallback to bypass 2FA if you have a phone number listed anywhere.

1. https://landing.google.com/advancedprotection/




Big benefit of Advanced Protection: you can go tell less technical users to set it up and it will enforce all these best practices (no SMS, two keys, no giving random apps access to GMail...).




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: